{"id":"CVE-2023-2017","aliases":["GHSA-7v2v-9rm4-7m8f"],"url":"https://o3.security/vulnerability/CVE-2023-2017","summary":"Improper Control of Generation of Code in Twig Rendered Views in Shopware","details":"Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\\Core\\Framework\\Adapter\\Twig\\SecurityExtension` and call any arbitrary PHP function and thus execute arbitrary code/commands via usage of fully-qualified names, supplied as array of strings, when referencing callables. Users are advised to upgrade to v6.4.20.1 to resolve this issue. This is a bypass of CVE-2023-22731.\n","published":"2023-04-17T10:18:27.543Z","modified":"2026-08-27T03:30:54.234203828Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.02066,"percentile":0.80144,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"shopware/platform","fixedVersion":"6.4.20.1"},{"ecosystem":"Packagist","name":"shopware/core","fixedVersion":"6.4.20.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://docs.shopware.com/en/shopware-6-en/security-updates/security-update-04-2023"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2017.json"},{"type":"ADVISORY","url":"https://github.com/shopware/platform/security/advisories/GHSA-7v2v-9rm4-7m8f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-2017"},{"type":"ADVISORY","url":"https://starlabs.sg/advisories/23/23-2017/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:30:54.234203828Z"}}